CVE-2006-7175
Summary
| CVE | CVE-2006-7175 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-27 23:19:00 UTC |
| Updated | 2008-09-05 21:16:00 UTC |
| Description | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 4.0 | update4 | All | All |
| Operating System | Redhat | Enterprise Linux | 4.0 | update4 | All | All |
| Application | Sendmail | Sendmail | 8.13.1.2 | All | All | All |
| Application | Sendmail | Sendmail | 8.13.1.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 172352 – (CVE-2006-7175) Sendmail allows SSLv2 during STARTTLS, and the CipherList config option isn't supported so you can't turn it off | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-04-27 | Mark J Cox | ** DISPUTED ** Sendmail classes the CipherList directive as "for future release"; currently unsupported and undocumented. Therefore the lack of support for the CipherList directive in various Red Hat products is not a vulnerability. |
There are currently no legacy QID mappings associated with this CVE.